CVE-2009-3978

medium

Description

The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.

References

https://wiki.mozilla.org/Releases/Firefox_3.5.5/Test_Plan

https://bugzilla.mozilla.org/show_bug.cgi?id=525326

http://www.mozilla.com/en-US/firefox/3.5.5/releasenotes/

http://www.h-online.com/open/news/item/Mozilla-fixes-critical-bugs-with-Firefox-3-5-5-852070.html

http://hg.mozilla.org/releases/mozilla-1.9.1/rev/edf189567edc

Details

Source: Mitre, NVD

Published: 2009-11-19

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Severity: Medium